What this website does with data – and above all what it does not do.
The controller within the meaning of the General Data Protection Regulation (GDPR) is:
No data protection officer has been appointed; the statutory conditions for doing so are not met.
That is verifiable rather than promised: the site consists of HTML, one stylesheet, a small script for the menu and our own image files.
This website keeps no access log. The web server is configured so that it writes neither IP addresses nor requested paths, user agents or referrers to any log file. No log files exist that could later be analysed or handed over.
What cannot be avoided is that the server knows your IP address while the page is being delivered – without it, it could not send the page back. It is processed in memory for the duration of the connection and not stored afterwards. The legal basis is Art. 6(1)(f) GDPR; the legitimate interest lies in operating the website.
Only when something goes wrong does the server write an error message. It records the cause of the error, not visitor data.
If you write to us, we process your e‑mail address and the content of your message in order to answer it. The legal basis is Art. 6(1)(b) GDPR where the enquiry relates to a contract or its initiation, otherwise Art. 6(1)(f) GDPR. Your message is kept until the matter is settled and no statutory retention periods stand in the way.
Please note that an unencrypted e‑mail is like a postcard. For confidential details we are happy to agree on a safer route in advance.
Addresses such as dapp.msolutions.bayern or next2bee.msolutions.bayern run separate applications. They are not public: without an invitation you only see a landing page. Those landing pages point here, which is why the access control is described in this policy – it does process data, however little.
When an invitation is redeemed, the server sets two cookies in your browser:
Both expire after one year and can be deleted in the browser at any time – the application is then out of reach until the invitation is redeemed again. They are strictly necessary within the meaning of section 25(2)(2) TDDDG, so no consent is required and none is requested. No cookies are set for analytics or advertising.
When an invitation is redeemed, the service called and the access name used are logged – without the IP address. This makes it possible to see whether a revoked access is still being used.
So that access names cannot be guessed by brute force, the server counts failed attempts per sender. The IP address is not stored for this: only a non‑reversible hash (SHA‑256) together with a counter. That entry expires after fifteen minutes at the latest. The legal basis is Art. 6(1)(f) GDPR; the legitimate interest lies in preventing unauthorised access.
Whatever you enter and store inside an application is governed by that application's own terms. In D’App and Next2Bee this content is end‑to‑end encrypted: on the server it is unreadable, to us as well.
Under the GDPR you have the right of access (Art. 15), rectification (Art. 16), erasure (Art. 17), restriction of processing (Art. 18), data portability (Art. 20) and objection to processing based on legitimate interests (Art. 21). A short e‑mail to msolutions@t-online.de is enough.
You may lodge a complaint with a data protection supervisory authority. For private bodies in Bavaria this is the Bavarian Data Protection Authority (BayLDA):
Bayerisches Landesamt für Datenschutzaufsicht, Promenade 27, 91522 Ansbach, Germany, www.lda.bayern.de
We update this policy whenever the website changes – for instance when forms, accounts or analytics are added. The version published here always applies.
Last updated: 30 August 2026